Coldcard Firmware Flaw Exposes $114M Bitcoin Theft, Accelerates ETF Shift
In brief
- Coldcard firmware flaw (March 2021) weakened seed-phrase randomness, enabling theft of 1,816 BTC ($114–$116 million) from 5,200+ addresses
- First attack wave (July 30, 2026) drained ~594 BTC ($38M) from ~500 addresses in 25 minutes; at least three waves identified
- Single-signature wallets bore brunt; multi-signature configurations offered protection compromised users lacked
- Spot Bitcoin ETFs and regulated custodians with insurance now more attractive to retail and institutional investors
The attack timeline and scope
The first major attack wave struck on July 30, 2026, draining approximately 594 BTC worth around $38 million from about 500 addresses in roughly 25 minutes. Galaxy Research later identified at least three separate waves of attacks targeting Coldcard users over the following days. The speed and scale of the initial onslaught underscored how thoroughly the attackers had mapped vulnerable wallets once the seed-phrase weakness became exploitable.
The attacks focused almost exclusively on single-signature wallets, the setup most everyday users run, without the additional security layers that multi-signature configurations provide. Users who'd layered on extra authentication—requiring multiple keys to authorize transactions—largely escaped unscathed. That disparity matters. It meant the victims were often the least technically sophisticated holders, those who trusted Coldcard precisely because it promised offline, air-gapped security.
Response and the custody question
Coinkite's CEO and the engineering team at Block both confirmed the bug's existence and issued emergency firmware updates. Yet the damage was done. The incident has crystallized a debate that's simmered in crypto for years: is self-custody actually safer than institutional solutions?
Spot Bitcoin ETFs already removed the operational burden of key management for institutional and retail investors who wanted Bitcoin exposure without managing private keys themselves. Now, after a $114 million theft from devices marketed as the gold standard for security, that value proposition looks sharper. Regulatory frameworks, insurance coverage, and multi-party computation or multi-signature custody arrangements operated by established firms suddenly appeal to a broader audience.
Institutional custodians stand to benefit most directly. Firms already operating under regulatory oversight, carrying insurance, and employing institutional-grade key management now have a stronger argument for why their model outweighs the appeal of self-custody. The Coldcard hack didn't invent that argument—but it gave it teeth.


